{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/define-supported-hyper-v-replica-use-for-dc-vms/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/",
        "slug": "define-supported-hyper-v-replica-use-for-dc-vms",
        "url": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/define-supported-hyper-v-replica-use-for-dc-vms/"
        },
        "title": "Define supported Hyper-V Replica use for domain-controller VMs",
        "summary": "Use Support for using Hyper-V Replica for virtualized domain controllers to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:15:10+00:00",
        "modified_at": "2026-08-27T12:56:25+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 514,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Support for using Hyper-V Replica for virtualized domain controllers",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Support for using Hyper-V Replica for virtualized domain controllers",
            "url": "https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/support-for-using-hyper-v-replica-for-virtualized-domain-controllers",
            "published_on": "2025-05-12",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to resolve one bounded operational decision: Define supported Hyper-V Replica use for domain-controller VMs. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/support-for-using-hyper-v-replica-for-virtualized-domain-controllers\" target=\"_blank\" rel=\"noopener noreferrer\">Support for using Hyper-V Replica for virtualized domain controllers</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>Hyper-V Replica asynchronously replicates selected VMs across LAN or WAN links. The research record locates this support at <strong>Opening overview</strong>.</li>\n<li>The document distinguishes supported and unsupported scenarios and requires Windows Server 2012 or newer domain controllers. The research record locates this support at <strong>Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios</strong>.</li>\n</ul>\n<p>These statements are the factual basis for this document. Do not extend them into a broader assurance. Review forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles only where the source and recorded environment align.</p>\n<h2>What the source does not establish</h2>\n<p>VM replication does not replace AD-aware backup, recovery planning, or replication-health monitoring. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity before translating the source into an operational decision.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Opening overview</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>What inventory proves which parts of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles are in and out of scope?</li>\n<li>Which condition in Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity must be healthy before evidence is trustworthy?</li>\n<li>What result would disprove the working assumption and return the issue to the owner?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles, observed and expected states, owner, and reason for deviation.</p>\n<p>Translate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity, while excluding secrets and sensitive personal or topology data from ordinary tickets.</p>\n<h2>Verification and evidence</h2>\n<p>Build a reproducible chain from <strong>Opening overview</strong>; <strong>Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios</strong> to the observed environment. Useful domain evidence includes directory and policy exports, replication and locator tests, event logs, trust state, role ownership, and controlled authentication tests; label every item with scope, timestamp, collector, and stable identifier.</p>\n<p>Close the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today&#8217;s observation is not a continuing guarantee.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/support-for-using-hyper-v-replica-for-virtualized-domain-controllers\" target=\"_blank\" rel=\"noopener noreferrer\">Support for using Hyper-V Replica for virtualized domain controllers</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to resolve one bounded operational decision: Define supported Hyper-V Replica use for domain-controller VMs. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Support for using Hyper-V Replica for virtualized domain controllers from Microsoft supports the following bounded statements:\n\nHyper-V Replica asynchronously replicates selected VMs across LAN or WAN links. The research record locates this support at Opening overview.\nThe document distinguishes supported and unsupported scenarios and requires Windows Server 2012 or newer domain controllers. The research record locates this support at Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles only where the source and recorded environment align.\nWhat the source does not establish\nVM replication does not replace AD-aware backup, recovery planning, or replication-health monitoring. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Opening overview, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles are in and out of scope?\nWhich condition in Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles, observed and expected states, owner, and reason for deviation.\nTranslate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity, while excluding secrets and sensitive personal or topology data from ordinary tickets.\nVerification and evidence\nBuild a reproducible chain from Opening overview; Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios to the observed environment. Useful domain evidence includes directory and policy exports, replication and locator tests, event logs, trust state, role ownership, and controlled authentication tests; label every item with scope, timestamp, collector, and stable identifier.\nClose the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.\nOfficial references\n\nSupport for using Hyper-V Replica for virtualized domain controllers — Microsoft",
        "content_markdown": "Use this document to resolve one bounded operational decision: Define supported Hyper-V Replica use for domain-controller VMs. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Support for using Hyper-V Replica for virtualized domain controllers](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/support-for-using-hyper-v-replica-for-virtualized-domain-controllers) from Microsoft supports the following bounded statements:\n\n- Hyper-V Replica asynchronously replicates selected VMs across LAN or WAN links. The research record locates this support at Opening overview.\n\n- The document distinguishes supported and unsupported scenarios and requires Windows Server 2012 or newer domain controllers. The research record locates this support at Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles only where the source and recorded environment align.\n\n## What the source does not establish\n\nVM replication does not replace AD-aware backup, recovery planning, or replication-health monitoring. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity before translating the source into an operational decision.\n\n## Applicability questions\n\n- For source statement 1 at Opening overview, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios, which observable configuration, record, or test can confirm applicability here?\n\n- What inventory proves which parts of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles are in and out of scope?\n\n- Which condition in Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity must be healthy before evidence is trustworthy?\n\n- What result would disprove the working assumption and return the issue to the owner?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles, observed and expected states, owner, and reason for deviation.\n\nTranslate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity, while excluding secrets and sensitive personal or topology data from ordinary tickets.\n\n## Verification and evidence\n\nBuild a reproducible chain from Opening overview; Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios to the observed environment. Useful domain evidence includes directory and policy exports, replication and locator tests, event logs, trust state, role ownership, and controlled authentication tests; label every item with scope, timestamp, collector, and stable identifier.\n\nClose the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.\n\n## Official references\n\n- [Support for using Hyper-V Replica for virtualized domain controllers](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/support-for-using-hyper-v-replica-for-virtualized-domain-controllers) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/",
                "url": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Define supported Hyper-V Replica use for domain-controller VMs",
                        "item": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/#article",
                "identifier": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/",
                "url": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/",
                "headline": "Define supported Hyper-V Replica use for domain-controller VMs",
                "description": "Use Support for using Hyper-V Replica for virtualized domain controllers to review this narrow operational decision without extending the source beyond…",
                "abstract": "Use Support for using Hyper-V Replica for virtualized domain controllers to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to resolve one bounded operational decision: Define supported Hyper-V Replica use for domain-controller VMs. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Support for using Hyper-V Replica for virtualized domain controllers from Microsoft supports the following bounded statements:\n\nHyper-V Replica asynchronously replicates selected VMs across LAN or WAN links. The research record locates this support at Opening overview.\nThe document distinguishes supported and unsupported scenarios and requires Windows Server 2012 or newer domain controllers. The research record locates this support at Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles only where the source and recorded environment align.\nWhat the source does not establish\nVM replication does not replace AD-aware backup, recovery planning, or replication-health monitoring. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Opening overview, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles are in and out of scope?\nWhich condition in Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of forests, domains, controllers, directory partitions, trusts, sites, replication links, service accounts, and delegated roles, observed and expected states, owner, and reason for deviation.\nTranslate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Windows DNS, time synchronization, network reachability, PKI, backups, virtualization safeguards, and privileged identity, while excluding secrets and sensitive personal or topology data from ordinary tickets.\nVerification and evidence\nBuild a reproducible chain from Opening overview; Sections: Windows Server 2012 or newer domain controllers required; Supported and unsupported scenarios to the observed environment. Useful domain evidence includes directory and policy exports, replication and locator tests, event logs, trust state, role ownership, and controlled authentication tests; label every item with scope, timestamp, collector, and stable identifier.\nClose the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.\nOfficial references\n\nSupport for using Hyper-V Replica for virtualized domain controllers — Microsoft",
                "datePublished": "2026-08-27T12:15:10+00:00",
                "dateModified": "2026-08-27T12:56:25+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/define-supported-hyper-v-replica-use-for-dc-vms/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Define supported Hyper-V Replica use for domain-controller VMs"
                },
                "articleSection": [
                    "IT",
                    "Microsoft 365 & Identity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Microsoft 365 & Identity",
                    "Networks & Infrastructure",
                    "Briefing",
                    "Advisory priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 514,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Support for using Hyper-V Replica for virtualized domain controllers",
                    "url": "https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/support-for-using-hyper-v-replica-for-virtualized-domain-controllers",
                    "datePublished": "2025-05-12"
                }
            }
        ]
    }
}